RansomwareSep 30, 2026
Global Group Ransomware Abuses WinMerge to Deploy Encryptor
Global Group ransomware uses WinMerge to deploy encryptor via payment-themed phishing.
Summary
Researchers at Cofense have uncovered a new tactic employed by the threat group Global Group. They are leveraging payment-themed phishing emails containing malicious ISO files that, when opened, utilize the legitimate WinMerge software to deploy their ransomware encryptor. This method targets large enterprises, aiming to extort them through ransomware attacks.
Indicators of Compromise
- malware — Global Group ransomware
Entities
Global Group (threat_actor)WinMerge (product)